Microsoft Defender for Endpoint Internal 0x06 — Custom Collection
ID: d485413b-be88-5dd9-97b7-d0d921085f40
STIX ID: report--d485413b-be88-5dd9-97b7-d0d921085f40
Feed Name: FalconForce
Microsoft Defender for Endpoint's Custom Collection lets teams define fine-grained telemetry rules that forward uncapped (subject to a 25k/day per-rule/device cap) event streams to Azure Sentinel as DeviceCustom* tables, providing an alternative to adding Sysmon or other agents. The article explains supported tables, licensing and agent requirements (Defender P2, Sentinel workspace, client v10.8805+), cost and operational considerations, and introduces TelemetryCollectionManager — a YAML-based Go tool to validate, deploy, export and manage rules (currently requiring a user token) with guidance to maintain rules in Git for versioning and review.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
